Commit graph

83 commits

Author SHA1 Message Date
Mikhail Novosyolov
8821206239 put ssh-askpass to libexecdir for compat with RH 2020-02-20 09:25:26 +03:00
Mikhail Novosyolov
d218e0156d More clean up 2020-02-20 09:18:14 +03:00
NixTux Commit Bot
89c79c35e0 bot: rpm5 -> rpm4 (8) 2020-01-13 16:36:16 +03:00
NixTux Commit Bot
31f0b9206d bot: rpm5 -> rpm4 (3) 2020-01-04 23:37:44 +03:00
NixTux Commit Bot
7f8dad67b4 bot: rpm5 -> rpm4 (1) 2020-01-04 05:10:45 +03:00
Алзим
41dc2d149e Updated to 8.1p1 2019-10-11 00:46:19 +03:00
Mikhail Novosyolov
8dafe20eae Fix CVE-2018-20685 2019-09-30 18:17:22 +03:00
Mikhail Novosyolov
3b6f385a11 Really apply patches, remove patch which refactors not existing code 2019-09-30 18:14:15 +03:00
Mikhail Novosyolov
c392516891 Add SELinux patches from Fedora 2019-09-30 02:43:46 +03:00
Mikhail Novosyolov
40fdc5f5d7 Add patch to work correctly with security-labelled TCP/IP packets 2019-09-30 02:36:10 +03:00
Alexander Stefanov
e43b1e0225 add selinux 2019-07-27 20:15:32 +00:00
Mikhail Novosyolov
9da2b298c3 Bump release after cherry-picking 4dd7e5f96a 2019-04-22 04:43:53 +03:00
Mikhail Novosyolov
cdab4d146b take last Port definition 2019-04-22 04:43:05 +03:00
Andrey Bondrov
aa12fa4be8 MassBuild#1671: Increase release tag 2019-04-14 01:44:38 +00:00
Mikhail Novosyolov
f7a578aaac Check if Avahi services directory exists and is writable 2019-04-12 20:11:53 +03:00
Mikhail Novosyolov
07d6ca5b5c Dynamically create Avahi service with correct sshd port after starting sshd, delete it after stopping sshd (RB#9855) 2019-04-12 18:22:40 +03:00
Mikhail Novosyolov
da7dda90e3 Rebuild with krb5-1.16.2 and openldap-2.4.46 2019-01-24 11:56:11 +03:00
Алзим
78983ea0d7 CVE-2019-6111, CVE-2018-20685, CVE-2019-6109, CVE-2019-6110 2019-01-16 20:12:22 +03:00
Mikhail Novosyolov
7088064a0a Fixed Description in sshd*.service 2018-11-22 21:18:16 +03:00
Mikhail Novosyolov
5179a7023c Fixed minor typos 2018-11-19 18:19:42 +03:00
Mikhail Novosyolov
383c996c5d Restart sshd only if was failed (after fixing host keys permissions) 2018-11-19 02:09:42 +03:00
Mikhail Novosyolov
725d8454a2 Fix host keys permissions on existing installations 2018-11-19 01:58:47 +03:00
Mikhail Novosyolov
3f824adc9e Revert "enabled kerberos support". This reverts commit 3d90d35df6.
I actually disabled kerberos, not enabled it.
2018-11-16 16:19:04 +03:00
Mikhail Novosyolov
c62fbe57cf Fixed dependency 2018-11-16 12:58:58 +03:00
Mikhail Novosyolov
f51f44221e Rebased patch for default configs. Added comment about ROSA-specific enabling of root login. 2018-11-16 12:32:15 +03:00
Mikhail Novosyolov
0632a1e45d Remove enot. It's not needed at the moment. 2018-11-16 12:20:33 +03:00
Mikhail Novosyolov
38d7f078a3 OpenSSH 7.0 depreceated DSA keys. Disabled them in sshd-keygen by default. 2018-11-16 12:20:08 +03:00
Mikhail Novosyolov
998f5d8009 openssh-server Requires enot (Inform users about regenerating SSH host keys) 2018-11-16 03:49:55 +03:00
Mikhail Novosyolov
ad37414d2a Fixed ok/error messages. Control resulting exit status properly. 2018-11-16 00:58:27 +03:00
Mikhail Novosyolov
c247c78986 Create DSA keys by default. Group ssh_keys does not exists, key files must belong to root:root. 2018-11-16 00:42:12 +03:00
Mikhail Novosyolov
c19f49453e Fixed permissions for private host keys (closes: https://bugzilla.rosalinux.ru/show_bug.cgi?id=9471) 2018-11-15 22:56:45 +03:00
Mikhail Novosyolov
fcae6e22fb removed unneded macros in URLs 2018-11-15 22:52:45 +03:00
Mikhail Novosyolov
3d90d35df6 enabled kerberos support 2018-11-15 22:47:06 +03:00
Mikhail Novosyolov
25f3b8c2a0 changed perl to sed to don't build-depend from perl 2018-11-15 22:41:08 +03:00
Mikhail Novosyolov
55c2aeac01 Synced sshd@.service with sshd.service. Added refenrence to docs to unit files. 2018-11-15 22:37:52 +03:00
Mikhail Novosyolov
15ef2709b0 Added openssh-7.4p1-systemd.patch from systemd (makes sshd send signals to systemd's sd_notify) 2018-11-15 22:31:35 +03:00
Mikhail Novosyolov
350690fb27 updated to 7.9p1. Dropped openssh-7.6p1-show-more-fingerprints.patch 2018-11-15 22:14:10 +03:00
Mikhail Novosyolov
6e1d225560 Initial changes to post-script. Don't generate host keys there, they will be generated automatically by sshd-keygen.service and must be different on every machine. 2018-11-15 11:37:34 +03:00
Denis Silakov
b3290edcf4 Enable GSSAPIAuthentication by default 2018-11-08 12:03:17 +03:00
Mikhail Novosyolov
aeb32c5d58 Use modern ssh-copy-id script instead of the very old one, which behaved differently from the modern one in other GNU/Linux distributions. 2018-10-28 22:50:17 +03:00
Алзим
16c6c6d21f Updated to 7.8p1 2018-09-06 10:21:51 +03:00
Andrey Bondrov
d59534c5de Update show-more-fingerprints patch to match 7.6 code base
Drop obsolete RSA1 parts
Add ED25519 parts
2018-01-24 00:15:04 +10:00
Andrey Bondrov
87fa3a7ab9 Update sshd-keygen to support ECDSA and ED25519 (with some other fixes from Fedora) 2018-01-23 20:25:41 +10:00
Andrey Bondrov
c7dd6d84a3 Drop exit-deadlock patch (now it only makes ssh client segfault) 2018-01-12 18:50:19 +10:00
Andrey Bondrov
a8b87a586c New version 7.6p1, re-diff some patches 2017-12-17 01:17:56 +10:00
Алзим
fabaed7f7b Updated to 7.5p1 2017-07-28 14:28:10 +03:00
Andrey Bondrov
c1b5642908 MassBuild#1230: Increase release tag 2017-02-04 18:30:34 +03:00
Andrey Bondrov
eb1afb2f25 Spec cleanup 2017-01-22 20:56:15 +10:00
Denis Silakov
ffed3bb90a Bump release 2016-11-27 16:21:48 +03:00
Denis Silakov
cc2bf8a9e8 Merge branch 'rosa2014.1' into rosa2016.1 2016-11-27 16:21:14 +03:00